Cookie consent in México
Consent and privacy law in México
Federal Law on the Protection of Personal Data Held by Private Parties since 2010
es-419
Who must comply
Private parties that process personal data in Mexico, including controllers and processors handling data of individuals in Mexico.
Penalties
Multas históricamente de hasta alrededor de 320,000 días de salario mínimo por violaciones graves
Key obligations
- Make a privacy notice available before collecting data
- Obtain express consent for sensitive personal data
- Honor the ARCO rights of access, rectification, cancellation and opposition
- Appoint a person or department for personal data protection
- Adopt security measures appropriate to the data
Local guidance
- Publicar un aviso de privacidad completo
- Usar consentimiento expreso para datos financieros y sensibles
- Proporcionar los avisos en español
- Dar seguimiento a la reestructuración de la autoridad mexicana de protección de datos
How ConsentX helps
- Privacy-notice-first banner shown before collection
- Express opt-in capture for sensitive categories
- ARCO rights request intake and workflow
- Consent and notice receipts for evidence
- Region rule engine tuned for Mexico
We value your privacy
We ask for your consent before any non-essential cookie, with the rules that apply in your region.
This page was machine-translated and may contain errors. Please review the legal details with qualified local counsel before relying on it.
How to comply with Mexico using ConsentX
- 1
Scan your website
Run a free scan to find every cookie and tracker on your site, so you know exactly what needs consent under Mexico.
- 2
Show a geo-aware consent banner
Add the ConsentX banner. It detects each visitor region and shows the consent experience that Mexico requires, automatically.
- 3
Block trackers until consent
Keep non-essential cookies and trackers blocked until the visitor agrees, so nothing fires before consent.
- 4
Record tamper-evident proof
Every choice is stored as a tamper-evident consent receipt you can produce in a Mexico audit.
- 5
Handle data requests on time
Use the built-in DSAR workflow with SLA timers to answer access, deletion and opt-out requests within the legal deadline.
Frequently asked questions
¿Qué es un aviso de privacidad?+
Es la notificación de privacidad obligatoria que exige la ley mexicana. Debe informar claramente a los titulares qué datos se recopilan, las finalidades y cómo ejercer sus derechos, y constituye una obligación central de cumplimiento.
¿México exige consentimiento de tipo opt-in?+
Para los datos ordinarios, el consentimiento puede ser tácito, lo que significa que el silencio tras un aviso de privacidad puede bastar. Se requiere consentimiento expreso para los datos financieros y consentimiento por escrito para los datos sensibles.